New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Toward Metadata Anonymity: disrupting the kill chain by Sterlin Lujan // W3PN Meetup Rome 2026

Ethereum Cypherpunk CongressTue, Jun 9, 2026, 12:00 AM

Web3Privacy Now Meetup Rome 2026 "Shaping and Defending the Techno-Political Evolution: Cryptography, Open Source, and Public Goods" Hosted by Web3Privacy Now ​​​Half-day dedicated to fostering solidarity among: ​​​- zk researchers and applied cryptographers ​- open source and human rights advocates ​​​- developers and hacker culture ​​​- internet freedom and grassroots movements ​​​- hacktivists and the general public Join us in building a free internet for all. Website: https://web3privacy.info/

Transcript

Cool. So, I don't I see a lot of new faces here. I don't know if you guys are familiar with me or my work or who I work with. My name just I'm going to do this very briefly. My name is Sterling Lujan.

I work with Logos on the movement team. We are I work specifically on the activist component of Logos where we're developing these local initiatives all around the world to empower local communities and to bring privacy, anonymity, and Cypherpunk ideas and ideology and philosophies back to those communities. So, what I'm going to what I'm here to talk to you guys to today about is not a fun subject at face value, but it's something that's really important that we have to talk about. So, I'm going to give you a little bit of a black pill, but then we're going to move into something that is a bit more positive, and that's the future. So, who here is familiar with the concept of a kill chain by show of hands?

Okay, so this is this is good then. Okay, so the former director of the CIA, Central Intelligence Agency in the US, he said that we kill people based on metadata. He didn't say that as an apology. He was bragging on a panel talking about the capabilities that the United States military currently has. And so, one of the things that the CIA in conjunction with the US Department of Defense and the US military is that they conduct drone bombing campaigns in the Middle East based on this this architecture that they have developed over time called FEED, and FEED stands for find, fix, finish, exploit, analyze, and disseminate.

The reason that this is important for us to understand is the find piece is critical because understanding it means that we don't only understand how the US conducts these activities, but we also understand that the surveillance apparatus of fine is deeply embedded in the surveillance apparatus that's also used domestically, not only in the US, but in the but in the EU, in China, in many different places, even if it's iteration and its examples are different. So, today what we're going to talk about is we're going to really unpack this concept. And by the way, you guys, this is supposed to be a conversation. So, if I say something you have a question, feel free to butt in. I'm 100% cool with it.

So, we're going to look at the threat model. Then we're going to look at the architecture, like the architectonics of being able to fight back against the system, but not only fight back uh to create alternatives to where we don't have to deal with these systems that can actually threaten our physical well-being. And this is speaking aside from just the privacy component. And then we're going to look at the civilizational structure, the future of society that we're trying to craft. And I believe that all of us here have the power and the capacity and the brilliance and the beauty to make it happen.

And I think we're in a very good position not only as workers in the cryptocurrency blockchain ecosystem, but just as people living on the front lines in a time where developing this kind of technology matters. Okay, so I mentioned feed earlier. So, let's let me explain how this system works. So, with the fine component, the US government does not care. This is the most important thing I tell you.

They don't really care about the content of messages. Most of our privacy preserving applications are very much focused on the the content, right? The the message that you send over a communication app, the message you send over social media, the financial transaction data that you send via a blockchain. What matters to the military, and this is also very relevant for just normal privacy, is the metadata. Metadata defined is just the the information or the data about data or information.

So, it's addresses, uh call times, call links, timestamps. These are the things that matter for the purpose of conducting surveillance on individuals. And so, what how the CIA in conjunction with the US military has developed these these techniques is that they, for one, they leverage SIM data on phones, right? Phones are constantly hitting towers at a particular cadence, and that information is taken in as data. Okay?

They also are very interested in developing what they call a pattern of life analysis, and they do this through the relationships that you have with other individuals, the connections that you have with human beings. The and they do this through tracking your messages, your the message content, the or sorry, the message data, the message timestamps. They don't care Again, they don't care about the actual content of these messages. And they also do this through Well, actually, there's a there's another important before I get to this. So, one of the important things here is like the actual person behind the metadata doesn't matter.

They're conducting what they call a signature analysis. So, they're looking at the combination of all the data points, and they're putting that together to develop what they refer to as a targeting package, right? So, that way they can conduct a targeted strike and hit somebody and assassinate somebody. But, the key here is like ultimately they've they've conducted a bunch of these strikes, and they have killed innocent bystanders. They've also targeted American citizens overseas and killed them also as a result of these strikes, all based on this metadata analysis, all based on these surveillance regimes.

All right, so I'm going to I'm going to try to end the black pill piece now here, but the important component of this is this same architecture is the architecture that they used to the just generally surveil the population. This is the same thing that Edward Snowden revealed early on when he talked about XKeyscore that he's also ranted about at length in his book Permanent Record, which I highly recommend checking out and looking into. All right, so let's talk about how we can move beyond this. I could drone on about the the really sad uh state of our state of affairs and state of our world, but let's think about how we can push back against this. And I think we're in a really nice position to develop novel institutions and novel technologies that leverage very strong anonymity engineering and privacy engineering that allow us to completely undermine and undercut the way that the surveillance apparatus has been deployed not only against people overseas in the Middle East, but also all of us who are activists and dissidents and have a stake to claim in defending our freedom, defending our autonomy, our free will, and our ability to take back agency and to reclaim our birthright as a species.

The first part of this, and I really love this technology, is mixnets, right? So who here is familiar with mixnets? Yeah. So the thing with with mixnets is that they experienced a period of some 15 years of stagnation where there was very little development being done, and it's just recently that development in mixnets have picked up, and now they're being uh productized in uh different formats. But the the The reason why mixnets are so important in terms of communication is that they're very explicitly developed for protecting our metadata.

And PGP or a peer mentioned earlier, David Chaum, was responsible for developing a lot of these primitives. He's actually responsible for creating some of the earliest versions of mixnets. If you guys are interested in leveraging a VPN that uses mixnets, our friend friends over at Nym and Harry Halpin have worked to develop a mixnet using Loopix. And Loopix is a mixnet architecture that was developed at the University College of London, which has a very specialized ways of helping to defend privacy. The name It's in the name, where a client sends messages repeatedly.

They're like fake messages. This is like fake fake traffic to throw off anyone who's an adversary who's trying to conduct traffic analysis. So, mixnets are one of the keys that I think we can be developing and working on to help protect and defend our metadata. Okay, this next part I'm going to slow down just a little bit because it's my favorite part of this discussion. So, the next tool that we have in our arsenal that is really seeing a lively discussion around and which people are extremely excited about is a zero-knowledge cryptography.

So, you guys are probably familiar with Eric Hughes, right? You've heard of Eric Hughes who wrote the Cypherpunk Manifesto. And Eric Hughes among a number of other people said that the property of privacy that's most important is the ability to selectively reveal yourself as you see fit. This is like one of the primary definitions of privacy. So, this is what zero-knowledge cryptography ultimately unlocks.

It allows us to reveal things about ourselves, reveal information or data without revealing other types of information. So, what I think is most important about zero-knowledge in this context is that we can create institutions that don't rely on the concept of state legibility for state actors and adversaries to be able to see different aspects of databases where information usually resides. And this also has key implications on protecting uh counterparty rights in terms of privacy because one of the things that these kill chain architects CIA etc. rely on is all of your business interactions, all of the databases that are queryable, that you are part of, that you are embedded in because these are effectively your permanent record. So, being able to leverage ZK to develop these novel institutions is key.

And I have a term for this. Uh you know, we hear a lot about this concept of oblivious messaging, this concept of oblivious data. So, I think what we're on the precipice of being able to build is oblivious institutions, like dark institutions that can allow a person to get a credential to receive a license, to get a role, or conduct a function without having to reveal a bunch of extraneous or unimportant information to that particular actor because even without thinking about the kill chain architectures, all of these these centers where data is housed or warehoused, regardless of bank institutions or literal data warehouse, are just honey pots for these actors to come out and just steal our our information. So, being able to leverage ZK for this intended use case is really important. I think there's a lot of interest in using ZK to for scalability purposes, like on Ethereum L2s, but I think it's even more vital and critical that we're working on ZKs for the privacy potential and the ability to protect our data on a fundamental level.

And I hope you vibe with me on that because I think it's really important. All right, the last piece here, the communication, the relational, and now the the economic. So in So transaction metadata, of course, is something that we have to pay attention to because that can also be used to triangulate a kill chain structure, and can also is also, of course, just used in any kind of like criminal investigation with regard to cryptocurrency regardless of you're innocent or you're guilty. So I think it goes without without saying we have to use a non as we have to use and build as many anonymized cryptocurrency platforms as possible. I'm personally a huge fan of cryptocurrencies like Monero for this use case and this purpose.

Also a fan of what the guys at Zano are doing, so I highly recommend looking into some of these technologies for off your skating your transactionality in order to protect yourself and your rights. Okay, so one of the important things that I want to mention, too, I think in the in the space, generally speaking, when it comes to cryptographers and uh security professionals, sometimes there's this all or none mindset where we have to have perfect cryptography and we can't leak any data or you're not really private. I think that type of maximalist thinking doesn't get us where we want to be in terms of being able to stop these kill chain architectures because, listen, the the way that these systems work is uh by uh statistics, by probability, right? They don't care about acknowledging the actual person on the ground. It's about the signature of the person, right?

So the cryptography doesn't have to be perfect. What needs to be better and what we all can continue to work on as our own operational security or OpSec. So this is just an aside that I want to mention. Very important that we just build the technologies and we make the spying and the surveillance apparatus as expensive and as cumbersome as possible because at that point it prevents these guys from being able to come after us in that way. All right, so now this is This is another important part of the discussion.

I'm going to step back and we're going to look at this more holistically and I'm going to get a a bit philosophical here. Uh who's who's familiar familiar with James C. Scott? Okay, so James C. Scott wrote a book called Seeing Like a State.

And his whole point of the book, he was like an anarchist scholar, a very well-respected guy. He uh wrote many articles and many books on uh a lot of it was the anthropology of the development of nation-states, uh nations generally speaking. The main point in his book Seeing Like a State is the idea that states only came into existence because they're able to uh codify individuals, they're able to gather data, they're able to corral people. It's a result of this that they they develop cadastral maps. It's the reason that the literally the surname that we all have surnames that exist because cuz that was a state-based activity.

A lot of people don't know that. And so what we're on the precipice of doing is creating a new civilizational order and social order where we completely undermine the state's ability to see, to analyze, to map us in a in a variety of different domains. And we we do this, we reach this point by unlocking the full potential of Mixnet's ZK uh privacy-empowered and privacy-enhanced cryptocurrency technologies. And we bring these together in the form of these oblivious or dark institutions. So, this is where I get to the point where I really believe that the nature of our civilization can change.

This is the thing, guys. This is a momentous occasion, right? We're we really are at a time period where we can express our full individuality, but we can also come together as a unified collective, as a group of people who care about who cares about liberty, who cares about privacy, who cares about freedom, and who overall wants to actively see lasting change, lasting paradigmatic shift. And so this message is not only about acting now, but it's also understanding that we have to choose the right technologies, and we have to build the right tooling based on those technologies. If we're not, I feel like we're going the wrong direction.

I was at the ZK summit I'm going to try not to talk too much I was at the ZK summit, and I felt like there was a like a very strong business focus there, especially with like layer two scaling, and the privacy concerns were almost absent from what I saw. I I hope that I'm fully wrong about that. Maybe I someone saw something I didn't see, but this is not the direction we don't need to be hijacked. We need to be pushing forward in a way that prevents our ecosystems from being hijacked. We have to completely embody the cypherpunk spirit.

We have to invoke people like Timothy May in the crypto anarchist manifesto. If we're not, we're going to lose ground, and we're not going to be able to continue pushing forward in the direction that we need to go. Thank you very much.

Automatic transcript — names and jargon may be misspelled.